Scope
This page supplements the Orbitra Privacy Policy by explaining how data may be used in connection with the website, demos, pilots, evaluations, customer-authorized product workflows, and Microsoft Teams setup and help interactions. Orbitra Security is a Canadian company and handles data under applicable Canadian requirements and customer agreements.
When a customer signs a separate agreement with Orbitra, that agreement controls any conflicting terms for customer data, product data, retention, security, and support.
Data Categories We May Handle
- Business contact data, such as name, work email, company, role, and communications.
- Demo request data, such as team size, use case, security priorities, and meeting notes.
- Customer-authorized identity security context, such as tenant configuration details, identity events, role or permission metadata, session context, application registration metadata, response records, and audit timelines.
- Operational data, such as logs, diagnostics, error information, usage metadata, and reliability signals.
- Optional website analytics, engagement, approximate location, and business-identity signals when a visitor accepts analytics.
- Support and success data, such as troubleshooting details, implementation notes, and customer feedback.
How We Use Data
- Provide demos, answer questions, and evaluate fit.
- Understand website engagement and follow up with potential business customers when optional visitor analytics are accepted.
- Connect to customer-authorized systems and perform requested security workflows.
- Map identity relationships, detect, triage, recommend, contain, verify, and document identity security events when authorized.
- Generate audit records, response timelines, and evidence exports.
- Maintain reliability, troubleshoot errors, secure systems, and prevent misuse.
- Improve product functionality, documentation, onboarding, and support.
- Meet contractual, legal, compliance, and recordkeeping requirements.
Operational Reports and Processing Location
Regional response and connection records use the Orbitra workspace's United States (AWS us-west-2) or India (AWS ap-south-1) home region. Shared ownership and authorization metadata use US services.
The Orbitra web application sends selected automatic error reports to its central support service in the United States for both United States and India workspaces. These reports help maintain reliability and investigate faults. Reporting operates independently of optional analytics choices and Do Not Track settings. Descriptions and attachments that you choose to submit in a support case are handled separately.
Automatic operational reports expire 14 days after they are first recorded; additional occurrences do not extend that expiry. Duplicate-detection receipts expire after one day, and temporary rate-limit records after two minutes. Expired records are removed by scheduled cleanup. These periods describe the operational tables and do not establish a deletion deadline for backups, security logs or separately submitted support cases. See Privacy for the restricted report fields and account association.
Teams Data Use
When Teams connections and guidance are enabled for your organization, the public bot callback and fixed setup/help replies are processed in the United States. This includes interactions from India workspaces and people who have not connected an Orbitra account. The privacy policy lists the information Microsoft may supply.
Guidance records hold an encrypted reply destination: Microsoft organization and conversation identifiers, the provider service address, team context when applicable, the original message reference for a reply, and any cleaned display name used for attribution. Separate hashes of inputs and installation context, timestamps, status and available provider message references help prevent duplicates and investigate uncertain outcomes. Hashes are pseudonymous identifiers, not a guarantee of anonymity.
A workspace connection uses separate authorization checks and regional records. Its selected notification channel may receive identity or incident context and a link to the source record in Orbitra. Shared ownership and authorization metadata use US services. Teams guidance itself does not read workspace incident data, grant access or make response decisions. A recorded provider message reference does not establish that a person received or read the message.
Teams Guidance Retention
The following thresholds apply to Orbitra's public Teams guidance records. Scheduled cleanup processes bounded batches, so a threshold is eligibility for cleanup rather than a guarantee of deletion at that exact time.
- A pending reply expires ten minutes after it is queued. Cleanup then suppresses the unsent reply and clears its encrypted context.
- Encrypted reply context becomes eligible for cleanup 24 hours after processing reaches a final status, including when a reply is recorded, rejected, left unconfirmed or not sent.
- Completed reply records, including any provider message reference, become eligible for deletion 30 days after that final status.
- Input hashes become eligible after 30 days from recording and after the linked reply records have been removed.
- Hashed installation markers remain while Orbitra records the installation as active. After an accepted removal closes that record, deletion becomes eligible 30 days after its last lifecycle change and after linked input records have been removed.
When Orbitra accepts a verified Microsoft app-removal event, it cancels applicable pending guidance and clears encrypted context for the affected earlier interactions in that transaction. Removal cleanup depends on receiving and validating that event; disabling the public callback prevents this event-based cleanup. Scheduled retention cleanup continues when new guidance replies are disabled.
The original callback body, authentication token, message text and setup code are not stored in the guidance records. These thresholds do not define retention for regional connection or alert records, shared authorization records, Microsoft-held messages, backups, security logs or separately submitted support cases. See Retention and security for the existing general retention description.
Guidance records can exist without an Orbitra account. For a request concerning such an interaction, use the privacy contact and request guidance.
AI-Assisted Analysis
Orbitra may use automated analysis and AI-assisted workflows to classify identity risk, summarize incident context, recommend response steps, and prepare audit-ready explanations.
Customer security data is used to provide, secure, support, and improve Orbitra services. Orbitra does not sell customer security data or demo request data.
Customer Controls
Customers decide whether to authorize a connection, what systems to connect, what response mode to enable, and what actions are permitted. Product workflows support observation, recommendation, approval and autonomous modes.
Customers are responsible for ensuring they have the rights and permissions needed to provide data to Orbitra and authorize requested workflows.
Limits on Use
- We do not sell visitor data, demo request data, or customer security data.
- We do not use customer security data to advertise unrelated third-party products.
- We do not intentionally collect sensitive personal information through the public website demo form.
- We use customer-authorized security data to operate, secure, support, and improve Orbitra, subject to applicable agreements.
Retention and Security
Retention periods may vary by data type, customer agreement, legal requirement, and operational need. When data is no longer needed, Orbitra deletes, de-identifies, or archives it according to applicable requirements and internal practices.
Orbitra uses reasonable safeguards designed to protect data from unauthorized access, loss, misuse, and alteration. Security controls may evolve as the product and company mature.
Contact
Questions about data use can be sent to hello@orbitrasecurity.com.
Last updated: September 7, 2026